Artificial intelligence (AI) is rapidly moving from experimentation to production across the federal government, and the changes are bringing new security pressures to an already complex environment. As government agencies connect generated AI tools and AI-enabled services to sensitive data and mission workflows, they need protections commensurate with the speed, scale, and ambiguity of AI threats. MeriTalk recently sat down with Anish Patel, Director of Federal Sales at Cloudflare, to discuss why shadow AI is often a signal of employee rather than rebellion. What does your AI-enabled security posture look like across human, prompt, and agent layers? And so on.
Meritalk: In your work with federal agencies, how have you seen AI change the attack surface? What new risks do you see emerging as agencies move from AI pilots to production systems that touch missions and citizen services?
Patel: AI is not necessarily changing the attack surface, just making it easier to attack. Vulnerabilities and exposure points have always existed, but what used to be necessary for attackers to take many coordinated steps can now be accelerated. This speed is important because it allows malicious actors to focus on more creative and harder-to-detect tactics.
In the pilot phase, agencies often treat AI like a sandbox. People are testing and experimenting, and important data may not always be valid. But once a government agency moves into production, its sandbox is connected to critical systems and the threat perimeter becomes more contextual. The analogy I use is the difference between protecting your child at home and protecting your child at the airport. At home, the environment is more controlled. There is always movement and unfamiliar actors at the airport. In the world of AI, the challenge becomes model addiction and prompt injection. The challenge is less about a new category of attacks and more about how difficult it is to decipher reality.
Meritalk: When you talk to federal security teams and AI teams, what are the blind spots when it comes to using shadow AI and GenAI?
Patel: Although Shadow AI is getting a lot of attention, it is basically no different from Shadow IT. And I think it’s important to reframe what that usually means. People who operate outside of a provisioned process usually don’t do it out of rebellion. With Shadow IT, we hear a lot of calls for help. People are trying to meet mission deadlines, but they don’t have the right tools or don’t have immediate access, so they look elsewhere.
The difference with Shadow AI is that small mistakes can be amplified faster. Decades ago, errors might have remained local and gone quickly. Today, mistakes can be widespread and persistent. An innocuous copy-and-paste moment can become a huge problem for your organization.
The question is not whether shadow usage occurs, but because it does. Rather, it’s about whether the government agency has visibility and control. The federal government already has a strong focus on security controls, allowing agencies to redirect users to sanctioned tools and make it easier to take advantage of sanctioned paths.
Meritalk: What does a robust AI security posture look like in a federal environment? In light of current federal guidance, how should agencies think about protecting AI agents that access employee interactions with GenAI tools and application programming interfaces and data stores?
Patel: The Office of Management and Budget’s guidance on accelerating the federal government’s use of AI through innovation, governance, and public trust focuses on enabling innovation, not just regulating it. The real challenge is finding the balance between maintaining strong security controls and not slowing down innovation. Historically, security tools have improved monitoring and control, but manual reviews of compliance, security, and policies can take months. In the field of AI innovation, these reviews need to be significantly sped up.
A robust attitude follows the OODA loop approach: Observe, Direct, Decide, Act. I think about managing AI risks hierarchically. The first is the human layer. Ensure only authorized staff can access authorized AI applications within your perimeter.
The second layer is the prompt layer. Define inline guardrails to prevent users from going out of bounds when interacting with your model. I liken these guardrails to digital TSA officers. People may not like friction, but there’s real value in making sure everyone understands what’s not allowed.
The third layer is the agent layer, where systems communicate with other systems on behalf of people. Without humans involved, the risks are exponentially greater and it becomes harder to spot malicious activity before it goes too far. Government agencies therefore need to both prepare for this regime and improve processes that don’t drag on traditional baggage. The technology is rarely the most difficult part. integration and process change. The goal is solid risk mitigation that allows government agencies to simplify processes not designed for the AI era.
Meritalk: Cloudflare’s platform secures both employee use of AI tools and AI-enabled applications. Can you describe the core capabilities of Cloudflare’s AI security suite and how those capabilities address the needs of federal agencies?
Patel: Start with a use case. We worked with a highly regulated entity that was concerned about data infiltration into large publicly available language models. When private data enters a public model, it can be received by anyone who queries related information. Cloudflare can enable visibility tools, and since we are exposed to so much traffic heading to the internet, agencies can use AI tools to discover employees. In this case, the user was pushing data to over 150 different public AI services without authorization.
Blocking everything won’t work. Because people will find other ways to get what they need to accomplish their mission. Instead of a whack-a-mole strategy, we focus on a visibility and reliability scorecard approach. Government agencies can see what tools their employees are accessing, define which AI tools are safe and allowed, and set zero trust policies to allow those tools. Agencies can then apply data loss prevention policies to automatically redact sensitive project names and personally identifying information that may be pasted into prompts. Work continues, but the risk of accidental exposure is reduced and quantified.
At a higher level, we address four key AI security themes: The first is to protect your employees’ use of GenAI tools. The second is securing interactions between AI agents and enterprise resources in a machine-to-machine world. Third, protect AI-powered apps like agency chatbots and AI-enabled services from data loss and attacks. And fourth, use AI to help developers build faster without compromising security. The goal is to harmonize security policies across public access, employee access, and developer needs, regardless of whether traffic flows inside-out or outside-in.
Meritalk: Without naming names, can you share an example of how a public sector or highly regulated customer has used Cloudflare and what kind of visibility and risk mitigation has been gained?
Patel: One of the challenges for governments is the need to make some of their data public. If users ask the right questions, AI can help analyze that information, but there still needs to be a filter between the user, the application, and the data.
Cloudflare is a filter for some resellers. This enables accurate logging of all applications being accessed, visibility into which services are heavily utilized, and the ability to clearly identify accesses that should not occur, such as external attacks on internal systems. This visibility creates real security value. With Cloudflare, the agency sets the standards for access, and as long as they are met, users can get through without a hitch. This filtering helps government agencies innovate without compromising security.
Meritalk: How do you expect the AI security challenges to change for federal agencies over the next two to three years, and how do you think the industry will respond?
Patel: Attacks that may have taken years to develop and propagate can now be accelerated, and the volume and velocity of attacks increases dramatically as more people gain knowledge. The question is how do you filter the noise when the level of attack activity becomes very high? As AI accelerates more complex attacks, government agencies need systems that can handle scale and complexity without drowning their teams in the noise.
At the same time, AI applications are also changing. Developers aim for applications that can be extended and customized not only by developers but also by end users. This means that security issues are no longer one application accessed by millions of users, but potentially hundreds, thousands, or even millions of iterations of the application accessed at scale. Traditional review cycles don’t work. Humans won’t be able to catch up. To protect against AI, we need AI. A modern approach that enables just-in-time authentication and auditing and maintains the boundaries between private and public without compromising the user experience will be essential.
And user expectations change quickly. Right now, people tolerate AI interactions that take a minute. Over the next year or two, people will begin to expect immediate responses. This makes programmability, real-time guardrails, and policy enforcement even more important because speed cannot be achieved at the expense of trust.
